# CVE-2026-28318

## Summary

- **CVE ID:** CVE-2026-28318
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-400
- **Published:** Jun 4, 2026
- **Last Modified:** Jun 6, 2026

## Description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

## Affected Products

- SolarWinds — Serv-U (15.5.4 and previous versions)

## References

- [CNA](https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318)
- [CNA](https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 40.01%
- **EPSS Percentile:** 98.5

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jun 5, 2026
- **Due Date:** Jun 19, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._